Ninja Forms plugin flaw exploited to hack WordPress sites
Hackers exploit stored XSS in Ninja Forms and a WooCommerce plugin to backdoor WordPress sites and hide admin accounts.
Patchstack reported attackers exploiting stored cross-site scripting flaws in two WordPress plugins to install backdoors and rogue administrator accounts. CVE-2026-94504 affects Ninja Forms 3.15.3 and earlier, used on more than 500,000 sites, and CVE-2026-93836 affects WPC Product Bundles for WooCommerce 8.6.6 and earlier, on more than 30,000 sites. Both require an authenticated session. A shared JavaScript payload from imgcdn1.com, first seen October 4, installs a fake WP Smart Thumbnails plugin, creates a hidden administrator and secret login, and exposes an unauthenticated file manager. Exploitation is currently limited; sites should update to Ninja Forms 3.15.4 and WPC Product Bundles 8.6.7 or later and check for compromise, because patching does not remove infections.